Dual Security Processor ATM Cash Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automated Teller Machines (ATMs) face vulnerabilities in cash handling operations due to exposure of cryptographic techniques and keys during authentication, maintenance, and remote software loading, making them susceptible to criminal compromise.

Innovation Solution

A valuable media handling device with dual security processors, where a master processor outside the safe controls and validates operations via an internal bus connection with a slave processor inside the safe, reducing exposure and enhancing cryptographic security through real-time encryption and tamper-responsive key erasure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single security processor is used in the recycler component, then authentication operations can be performed, but cryptographic techniques and keys are exposed during authentication, maintenance, and remote software loading

Engineering Contradiction:
Improvesecurity of authentication operationsVSAvoidexposure of cryptographic keys
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security processor is divided into two separate entities: a first security processor located outside the safe and a second security processor located inside the safe. This segmentation isolates the cryptographic keys within the second processor, preventing exposure during maintenance and remote software loading operations performed on the first processor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cryptographic keys and sensitive authentication data are extracted from the first security processor and stored exclusively in the second security processor inside the safe. This extraction ensures that keys are not exposed during routine maintenance or remote software updates of the first processor.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If independent authentication is performed by each component, then security validation is thorough, but the exposure of cryptographic keys increases during each authentication operation

Engineering Contradiction:
Improveauthentication validationVSAvoidexposure of cryptographic techniques
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The first security processor acts as an intermediary that handles authentication operations without containing the actual cryptographic keys. It communicates with the second security processor inside the safe, which holds the keys. This intermediary arrangement allows authentication to proceed while keeping keys isolated and protected.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If cryptographic keys are stored in the recycler component, then authentication can be performed, but keys are exposed during maintenance and remote software loading

Engineering Contradiction:
Improveauthentication capabilityVSAvoidexposure during maintenance
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system is segmented into two security processors with distinct roles: the first processor outside the safe handles operational authentication tasks, while the second processor inside the safe securely stores cryptographic keys. This segmentation allows maintenance and remote software loading on the first processor without exposing the keys in the second processor.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11210909B2Valuable media handling device with security processor
Publication Date: 2021.12.28 NCR ATLEOS CORP
  • US11210909B2 patent drawing
  • US11210909B2 patent drawing
  • US11210909B2 patent drawing

AI summary

A valuable media handling device is presented having two security processors. A top box for an escrow module of the valuable media handling device includes a master security processor. The master security processor is connected to a slave security processed located within a safe of the valuable media handling device via an internal bus connection. The master security processor controls and validates operations and modules of the valuable media handling device and the slave security processor controls and validates operations that access the safe for depositing or dispensing valuable media from the safe.